Martyn Simpson, Chief Information Security Officer

Martyn Simpson

Chief Information Security Officer
SaaS Security, Governance, Risk & Trust

I help SaaS leaders turn security, resilience and customer trust into practical business decisions, supporting enterprise growth, effective governance and transaction readiness.

My work spans board-level risk, customer assurance, governance, resilience and the decisions where commercial ambition meets responsible risk management.


Board and investor engagement

SaaS security leadership

Customer and commercial assurance

Governance and risk

Resilience and incident leadership

Transaction readiness

How I help

Security and risk governance

Helping leadership teams identify material security risk, make proportionate decisions and establish clear accountability.

SaaS trust and enterprise readiness

Building assurance and customer-trust approaches that support enterprise growth without creating unnecessary bureaucracy.

Resilience and critical decisions

Providing calm direction around incidents, vulnerabilities, business continuity, data governance and difficult technology-risk trade-offs.

Selected impact

Security programme

Built and matured the security programme for a growing B2B SaaS provider.

Board confidence

Led board and investor engagement across security, resilience, incidents and strategic risk.

Customer trust

Established a public Trust Center and customer-facing whitepaper series.

Commercial support

Supported material new and recurring revenue through enterprise assurance.

Compliance programmes

Led and supported programmes across ISO 27001, Cyber Essentials, Cyber Essentials Plus, ISO 9001, HIPAA and SOC 2 Type II.

Transaction readiness

Supported acquisition due diligence and engagement with prospective purchasers.

Selected work

Preservica Trust Center

A public assurance programme making security, privacy, compliance and resilience evidence more accessible to customers.

CISO Assurance whitepaper series

Practical whitepapers covering AI security, privacy, customer trust, data residency and access governance.

Speaking and commentary

Public discussion covering digital preservation, Microsoft 365, AI governance and long-term information risk.

Selective advisory

I am open to a small number of light-touch advisory relationships with SaaS and technology businesses that need pragmatic security, resilience or customer-trust guidance.

Latest Insight

The Difference Between Being Secure and Being Trusted

Security is an operating condition. Trust is a conclusion reached by somebody else. For SaaS businesses, credible assurance connects real controls to clear, useful evidence.

View all Insights or browse Technical Notes.